Most organisations deploy AI systems without a clear legal picture: Is this a high-risk AI system? Does it process personal data? Is a data protection impact assessment required, a fundamental rights impact assessment, or both?
These are not hypothetical questions – they are the ones regulators will ask. Our assessment gives you a concise, transparent evaluation of your existing or planned AI systems against both legal frameworks, so you have the answers ready.
Three Models – Choose What Works for You
Whether you already have a data protection mandate with us, need a one-off assessment, or only want the AI Act dimension reviewed: we offer the assessment in three models
Model 1
One-Off Project
A self-contained assessment of your currently deployed AI systems, with a clear start and end point.
- Inventory of AI systems
- Classification under the AI Act (Art. 5, 6, Annex III)
- Data protection assessment under the GDPR
- Final report with recommendations for action
Model 2
Extension of an Existing DPO Mandat
Do you already have an external Data Protection Officer with us? We integrate the AI assessment directly into your existing mandate.
- Use of the existing records of processing activities
- No duplicate onboarding – your familiar contact remains in place
- Synergies between the GDPR and AI Act review
- Predictable expansion of your ongoing consulting budget
Model 3
AI Act-Only Review Mandate
Is your data protection already covered elsewhere? We then focus exclusively on the AI Act compliance of your systems.
- Focused review without a full data protection mandate
- Classification, role identification, obligations catalogue
- Coordination with your existing Data Protection Officer possible
- Suitable as a precursor to an ongoing AI Officer engagement
What the Assessment Covers in Detail
AI Act Dimension
- Review for prohibited practices (Art. 5 AI Act)
- Classification as high-risk, transparency-obligated or minimal-risk system (Art. 6, Annex III)
- Role identification along the AI value chain (Art. 2(1) AI Act)
- Obligations catalogue: documentation, registration, conformity assessment
GDPR Dimension
- Review of the legal basis for data processing by the AI system
- Inclusion in the records of processing activities (Art. 30 GDPR)
- Assessment of data processing agreements with AI providers
- Determination of whether a data protection impact assessment is required (Art. 35 GDPR)
1
Brief Initial Consultation
We clarify scope, number of systems, and the appropriate model (1, 2 or 3).
2
Review & Assessment
Analysis of AI systems against the AI Act and GDPR, with specialist department consultation where needed.
3
Report & Recommendations
A clear final report with prioritised next steps with optional handover into an ongoing support engagement.
Frequently Asked Questions
Contact Us
Stay ahead of regulatory changes and unlock AI’s full potential while remaining compliant. Get in touch with our AI experts today for tailored guidance on implementing AI responsibly and in accordance with the AI Act.
Tania Vanessa Eslava Suarez, MLB, Lawyer
Senior Counsel
Email: teslava@re-move-this.first-privacy.com
Phone: +49 421 69 66 32-832
FIRST PRIVACY GmbH, Bremen
Cihan Parlar, LL.M.
Managing Director
Email: cparlar@re-move-this.first-privacy.com
Phone: +31 20 211 71 16
FIRST PRIVACY B.V., Amsterdam
Mag. iur.
Markus Strasser
Managing Director
Email: mstrasser@re-move-this.first-privacy.com
Phone: +43 662 62 10 04-11
FIRST PRIVACY Austria GmbH, Salzburg
If your inquiry concerns an organization based in Germany, these contacts will help you
Maximilian Eckardt, LL.B., Lawyer
Senior Counsel
Email: meckardt@re-move-this.datenschutz-nord.de
Phone: +49 30 308 77 49-13
datenschutz nord GmbH, Berlin
Daniel Hauk, Lawyer
Senior Counsel
Email: dhauk@re-move-this.datenschutz-sued.de
Phone: +49 89 200 08 86-785
datenschutz süd GmbH, München